Policies
Everything Dovri publishes about how member data is handled and protected. Each policy is a page you can read here and a document you can download.
Version 1.0 · Effective 9 October 2026
What Dovri collects, why, who else sees it, how long it is kept and how to have it deleted. Written for members rather than reviewers, and the retention periods in it match the retention policy below.
Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027
How security risks are identified, mitigated and monitored: risk register, access control, encryption, secure development and vulnerability remediation, third parties, logging, incident response, business continuity, and coordinated disclosure.
Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027
Who may reach Dovri systems and member data, how that access is authenticated, and how it is changed, reviewed and removed. Covers named accounts, least privilege, multi-factor authentication, machine credentials and member authentication.
Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027
How long each category of member data is kept, why, and how it is disposed of when the period ends. Includes the retention schedule, member deletion requests, legal holds and data minimisation.
Each policy carries a version number and an effective date. When a policy changes, the version is raised and the effective date is updated; the page and the downloadable document are always the same text.
Security questions, vulnerability reports and partner diligence: security@joindovri.com. Anything else: support@joindovri.com. Machine-readable contact details are at /.well-known/security.txt.